Skip to content

test(opencode): evaluate init-provisioned runtime and gcompat preload - #120

Closed
xnoto wants to merge 7 commits into
mainfrom
test/opencode-init-runtime
Closed

xnoto wants to merge 7 commits into
mainfrom
test/opencode-init-runtime

Conversation

@xnoto

@xnoto xnoto commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Owner-approved init-container feasibility experiment retaining the unchanged digest-pinned standard OpenCode 1.18.29 image. Test-only .github changes; no packaged chart adoption. Maintainer: makeitworkcloud.

BLOCKED: init preparation works, but the pinned memory native stack does not pass. The latest isolated Node probes reproduce ONNX1.20.1 import termination (exit139) and a separate libsql import missing __res_init; the actual preloaded OpenCode memory-only path panics with a C++ exception and exits132. No successful required B embedding/recall/warm-replacement gate exists.

The owner has deferred graceful-rollout design; it is not part of this change. ImagesPR58 remains closed and chartPR113/94 untouched. No custom image, alternate base, native binary patch/build, unofficial glibc, remote embedding or LLM/provider fallback is introduced.

Type of change

  • CI / reusable workflow
  • Documentation

Validation

  • Required pull-request checks pass — runtime gate failed, not waived.
  • Generated/centrally distributed files were not hand-edited.

Latest tested head 9015710e18258c7c4c7792bf7fb1380c3f52d8a8; base 45e027f44f9e3379634c5bcdfdbc8c876944de92. Normal PR runtime36376848803 terminal failure; Helm36376848798 terminal success. Cleanup succeeded. No local validation/manual dispatch/rerun.

Latest independent diagnostic cases reuse only a separate synthetic fixture's read-only public package/model cache, with no network and fresh /tmp. They are NOT substitutes for the actual OpenCode gate:

Diagnostic Result
@libsql/client0.17.4 Import fails: __res_init: symbol not found, child exit1; CRUD not reached
Sharp0.35.5 resolved by Transformers4.3.0 linuxmusl-x64 binding/libvips imported, one-pixel PNG operation returned90bytes, exit0
Direct onnxruntime-node1.20.1 Last marker onnx.import.before; child exit139 without after-import marker, session creation not reached
Transformers4.3.0 with the plugin's existing ONNX1.20.1 shim Shim completes, child exits139 at Transformers import; pipeline/inference not reached

All four Docker OOMKilled flags were false. Docker wait's exit0 only means waiting succeeded; child exit codes above are taken from Docker State. Actual OpenCode memory-only with documented GLIBC_FAKE_DEBUG still exits132 during /config, gcompat mapped; bounded crash evidence includes panic(main thread): A C++ exception occurred. Exact native instruction/throw site and whether Node139/Bun132 share one underlying cause remain unknown. Empty gcompat debug traces are not proof no native load occurred.

Prior isolation run36372981483 established that no-configured-plugin and context-only preloaded servers remained running for roughly111seconds; memory-only reproduced failure, so context-mode coexistence is not required. This is startup observation, not context host-dispatch correctness. Prior A/B run36371831454 measured init+inspection preparation2.985s, Abootstrap19.480s then missing __vsnprintf_chk; B mapped gcompat but exited132 before readiness. No successful warm timing exists.

An upstream gcompat source change adds __res_init, but the inspected Alpine3.24 stable package1.1.0-r4 does not carry that backport. No patched package was installed; such a fix would not prove working libsql CRUD or solve the independently reproduced ONNX import failure.

Pre-PR architecture/adversarial/security/DevOps reviews covered the bounded initial experiment; later diagnostic refinements were primary-reviewed. Reviews do not override failing CI or establish production readiness. Transitive package/model/APK inputs remain nonhermetic. No ARM64, Kubernetes storage, real conversation learning or recovery guarantees.

Impact and rollout

Changed paths: .github/workflows/opencode-init-runtime.yml and .github/tests/opencode-init-runtime/{runtime.py,prepare.sh,http.mjs,probe.mjs,diagnostics.py,native.mjs,README.md}. PR-only workflow, read-only GitHub permission, pinned checkout without persisted credentials. No image build/push, registry login or artifact/cache upload. No chart version bump or publication/GitOps handoff.

Original gate unchanged: A uses library paths and is diagnostic; B adds preload and MUST complete real write, exact-ID/content/finite-similarity recall, fresh-config/retained-HOME offline replacement, required inspections and cleanup. Diagnostic case success cannot turn B green. Setup/arm/diagnostic budgets are bounded by the50min job.

Production image/config/security and live service remain unchanged. Chart adoption needs a supported working runtime remedy and separate reviewed release/deployment decisions. No merge/publication/exec/sync/restart/live action. Closing this unmerged experiment leaves production unchanged.

Safety and secrets

  • No real secrets, decrypted SOPS, state, kubeconfigs or private endpoints; test API marker is public synthetic data.
  • No local OpenTofu operations run or claimed.
  • Effects, remaining gates and rollback boundary described above.

UUID disposable volumes, no production HOME/auth/data or Docker socket mounted. Application remains non-root/read-only, no host ports. Only bounded sanitized crash/error/version/stage evidence is retained, not raw config/auth/environment/maps or core dumps. Native diagnostics use networknone. Cold plugin/model egress remains public and unrestricted, an explicit pilot limitation. AI-assisted implementation and independent specialist scrutiny.

@github-actions

github-actions Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Chart CI passed

Repository hygiene and Helm validation passed. View the workflow run.

@xnoto

xnoto commented Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

Closing at the owner's request: stop this approach and revisit context-mode/opencode-mem at a later time using a different approach. No further implementation or adoption is authorized by the earlier experiment approval.

Nothing from this PR was merged or published; packaged chart defaults, GitOps selection and the running service were unchanged, so no production revert is necessary. The prior images PR #58 is already closed. Existing unrelated or older PRs are untouched.

Retaining branch test/opencode-init-runtime at 9015710e18258c7c4c7792bf7fb1380c3f52d8a8 and CI evidence for recovery/reference only. The failed compatibility gate is not waived. Do not reopen, publish, switch runtime bases or activate plugins without a fresh owner request.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant